security/keys/big_key.c in the Linux kernel before 4.8.7 mishandles unsuccessful crypto registration in conjunction with successful key-type registration, which allows local users to cause a denial of service (NULL pointer dereference and panic) or possibly have unspecified other impact via a crafted application that uses the big_key data type.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade linux | Jul 30, 2024 | Nov 28, 2016 |
| Ubuntu | — | Upgrade linux-image-powerpc-smpUpgrade linux-image-generic-lpaeUpgrade linux-image-4.8.0-32-generic-lpaeUpgrade linux-image-powerpc-e500mcUpgrade linux-image-powerpc64-embUpgrade linux-image-raspi2Upgrade linux-image-genericUpgrade linux-image-4.8.0-32-powerpc-smpUpgrade linux-image-4.8.0-32-powerpc64-embUpgrade linux-image-4.8.0-1021-raspi2Upgrade linux-image-4.8.0-32-powerpc-e500mcUpgrade linux-image-lowlatencyUpgrade linux-image-4.8.0-32-genericUpgrade linux-image-4.8.0-32-lowlatency | Dec 21, 2016 | Nov 27, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub